Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
WiliRGasparetto
MVP Diamond
MVP Diamond

Policy Auditor: Turning Access Control Policy Review into Intent-Based Segmentation Validation

Policy Auditor: Turning Access Control Policy Review into Intent-Based Segmentation Validation

 

One of the biggest challenges in firewall governance is not only building an Access Control policy.

It is proving that the policy still reflects the organization’s real security intent.

Over time, Rule Bases naturally grow:

  temporary rules become permanent;

  broad exceptions stay longer than expected;

  network segmentation changes;

  cloud and branch connectivity expand;

  business applications require fast changes;

  old rules remain because nobody is fully sure if they can be removed.

The result is a very common gap:

The segmentation model the organization believes it has
is not always the same as
The Access Control Rule Base that is actually implemented


This is where Policy Auditor, introduced with R82 Jumbo Hotfix Accumulator Take 103, becomes very relevant.

Policy Auditor provides a structured way to compare the Access Control Rule Base against defined organizational guidelines, helping administrators identify policy violations and improve policy consistency.

1 What problem does Policy Auditor solve?

Traditional firewall reviews are usually rule-centric.

We look at:


Rule number
Source
Destination
Service
Action
Install On
Hit count
Last used
Comments

That is important, but it does not fully answer one critical question:


Should this traffic be allowed between these network segments?

Policy Auditor changes the perspective from only reviewing individual rules to validating traffic flows between defined network segments.

Examples:



This makes the review much closer to the real segmentation and Zero Trust model of the organization.

WiliRGasparetto_0-1783430200909.png

 

2 The Policy Auditor workflow

The workflow is simple and very powerful:

 

WiliRGasparetto_1-1783430200947.png

 

Each segment represents a distinct part of the network, such as:


DMZ
Data Center
Branch Offices
User Networks
Public Cloud
OT Network
Management Network
Partner Network

After the segments are selected, Policy Auditor creates a matrix.

Each cell in the matrix represents traffic:


From one segment to another segment
or
Within the same segment

For each cell, the administrator defines the intended behavior:


All traffic is allowed
All traffic is not allowed
Decide later

This is important because the audit starts from the intended security model, not from the existing rules.

 

3 From Rule Base review to intent-based validation

 

The main value of Policy Auditor is that it helps answer a better question.

The old question:

Is this rule being used?

The better question:

Should this rule allow traffic between these segments?

A rule can be technically valid and still violate the security architecture.

Example:


Source: User_Networks
Destination: Data_Center
Service: Any
Action: Accept

 

This rule may work from a connectivity perspective.

But it may be wrong from a segmentation perspective if the organization expects only specific services to be allowed.

For example:


HTTPS to approved applications
DNS to approved resolvers
NTP to approved servers
Monitoring to approved collectors

Policy Auditor helps expose that difference.

4 How guidelines are created

In SmartConsole, Policy Auditor is available under:

 

WiliRGasparetto_2-1783430200980.png

 

 

 

The administrator creates a guideline and adds the relevant network segments.

Each segment is represented by a Network Group object, which contains IP addresses and networks.

The same guideline can be assigned to one or more Policy Layers.

This is very useful in environments with multiple Access Control layers or different policy packages.

WiliRGasparetto_3-1783430200986.png

 

 

WiliRGasparetto_4-1783430200992.png

 

Once the guideline is created, Policy Auditor builds the matrix.

By default, traffic within the same segment is allowed.

For each source/destination cell, the administrator can define:

All traffic is allowed
All traffic is not allowed
Decide later

WiliRGasparetto_5-1783430200997.png

 

5 How Policy Auditor identifies violations

Policy Auditor evaluates the rules in the selected Policy Layer against the guidelines.

A rule that does not comply with the guideline is marked as a violating rule.

The key logic is important:


An Accept rule is presented as a violating rule
if there is no Drop rule above it within the scope of the cell
that fully covers its source, destination and services.

An Accept rule is not presented as a violation only if a single Drop rule above it fully covers:


Source
Destination
Services

One important detail:

 

If the coverage is split across multiple rules above it,
the Accept rule is not marked as a violation.

This behavior is important to understand before interpreting the results.


6 Auditing the Rule Base

After the guideline is created, the administrator selects the Policy Layer and clicks Calculate.

Important:

If there are unpublished changes, they must be published first.

For each calculated cell, Policy Auditor shows:

All rules
Violating rules
Approved violations

This gives a practical view of which rules are associated with the selected segment-to-segment flow and which rules violate the defined intent.

WiliRGasparetto_6-1783430201004.png

 

 For each violation, the administrator has three possible decisions:

 

Approve the violation
Change the rule
Change the guideline

That is an important operational point.

Not every violation is necessarily wrong.

Some exceptions may be legitimate.

But they need to be governed.

A good approved violation should have:

 

Business justification
Owner
Scope
Risk acceptance
Review date
Change reference

Policy Auditor helps move exceptions from “hidden in the Rule Base” to “visible and auditable”.

 

7 Why this matters for security architecture

Many organizations have network segmentation diagrams.

But the real question is:

Does the Access Control policy actually enforce that segmentation?

Policy Auditor can help validate flows such as:

Can the DMZ initiate traffic to internal networks?
Can User Networks reach OT directly?
Can Branch Offices talk directly to each other?
Can Public Cloud workloads reach Management Networks?
Can temporary exceptions bypass the intended segmentation model?

This is very valuable for:

* security architecture;
* Zero Trust initiatives;
* firewall governance;
* rule recertification;
* audit readiness;
* compliance reviews;
* reducing excessive access;
* identifying segmentation drift.

Continues in the next post, in Part 2.


(2)
3 Replies
murilomuinhos
Participant

Great Job @WiliRGasparetto !!!

WiliRGasparetto
MVP Diamond
MVP Diamond

Thank you, @murilomuinhos

WiliRGasparetto
MVP Diamond
MVP Diamond

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events